Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 297

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Analysis: Chairman Kevin Warsh’s task forces are the key to understanding the new Fed
Financials have the market's deepest bench of near-breakouts
Chairman Warsh abstains from giving rate forecast as several members signal a hike in 2026
Fed holds rates steady, pares down statement to remove cutting bias
Stargate SG-1: Desparate Measures Rewatch
What would happen if the POTUS started shooting people in the streets?
Separating hobby and work
Treasury 2-year yield post-Fed spike 'exaggerated' or is there room for more? Strategists weigh in
China to return as major oil buyer in August, JPMorgan says, naming its top stock picks
Defense contractors would be barred from buying back their stock in bill approved by Senate panel